FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
A_dhanda
Staff
Staff
Article Id 216702
Description This article describes the scenario of being unable to create a Wildcard type FQDN using characters like '/' in FortiOS 6.4 & further.
Scope FortiOS 6.4 and above.
Solution

Starting FortiOS 6.2, the Wildcard FQDNs can be created in the address object & hence used in the policies as the destination.

 

In this branch, creating a Wildcard FQDN address allowed using characters like '/' even though in the background this never worked and the FQDN will be at Unresolved state, but from FortiOS 6.4 & further, this is not supported in the address object creation phase.

 

Even though the 6.2 branch allowed such characters but they never resolve to an IP address.

 

So, even if the character is allowed initially, but it never worked in the resolution of the FQDN to IP addresses as FQDNs are domains and cannot include such characters as this characters points to an specific path/ subdomain.

 

This is an example from the 6.2 branch indicating the successful usage of characters like '/' in the Wildcard FQDN Object.

 

A_dhanda_0-1656951692121.png

 

A_dhanda_1-1656951692124.png

 

This is no longer possible with the successor branches like FortiOS 6.4 & further. When using '/' in the Wildcard FQDN type object, this is not supported anymore to be used in the address object in the first place, and this is an error that can be observed as well.

 

A_dhanda_0-1656952449743.png

 

Since having such characters never added a technical value to the syntax & the resolution to an IP, this is no longer supported from FortiOS 6.4 & further.

 

Contributors